THE CRUNCH

The Cybersecurity and Infrastructure Security Agency (CISA) has launched its annual Cybersecurity Awareness Month with a new theme, Securing the Next 250. The campaign urges organisations that own or operate critical infrastructure to adopt foundational security practices, such as teaching employees to spot phishing, using strong passwords, enabling multifactor authentication, and keeping software updated. CISA Acting Director Nick Andersen emphasised that disruptions to critical infrastructure, including clean water and healthcare, have immediate impacts on communities. The agency also highlighted the importance of logging, data backups, encryption, and having an incident response plan. For infrastructure owners, CISA introduced the 3Rs of Cybersecurity: Reduce attack surfaces, Replace end-of-support devices, and Recover quickly.

CISA has updated its awareness toolkit with resources tailored for business and government organisations. The agency is encouraging critical infrastructure operators to adopt the 3Rs of Cybersecurity: Reduce attack surfaces, Replace end-of-support devices, and Recover quickly. It also advises government entities to consider using a .gov domain for added security and to report incidents to CISA.

The campaign comes at a time when nation-state backed cyber threats are increasing and super intelligence is transforming the threat landscape. CISA stressed that every organisation touching critical infrastructure plays a vital role in sustaining essential services. The agency recommends that incident response plans be reviewed and drilled on an annual basis at a minimum.

WHAT HAPPENS NEXT

CISA will host events and share resources throughout October 2026 to support the campaign.